Investigate malicious npm packages and AI-agent policy findings. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision. Malware findings and policy violations are labelled separately.
Updated 11 Oct 2026, 21:38 UTC. Ordered by latest scan.
The package silently exports mail account configuration, including possible IMAP passwords, to an unrelated remote logging endpoint during normal runtime. This is concrete credential exfi...
The encrypted remote redirect and query-parameter forwarding are concrete deceptive browser attack behavior. Although npm installation has no lifecycle execution, publishing this package...
The exported hidden-SVG evaluator is a concrete arbitrary-code-execution capability and is not needed for SVG processing. Although it has no install hook or observed exfiltration, its del...
Although it has no install hook or network activity, the source implements concealed, hostile browser UI lockout behavior. The obfuscated published bundle corresponds to the readable sour...